Which Audit Type Compares Security Policies to External Regulations?
The Chief Information Security Officer (CISO) at a large company would like to gain an understanding of how the company's security policies compare to the requirements imposed by external regulators. Which of the following should the CISO use?
Community Votes
62% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests the logical sequence of compliance activities, trapping candidates who fall for the 'external regulators = external examination' keyword match instead of recognizing that internal audits are the standard, cost-effective method for initial policy-to-regulation alignment.
This question evaluates the distinction between internal audits and external examinations in regulatory compliance workflows. The community consensus strongly favors internal audit, highlighting that organizations conduct self-assessments first to identify gaps between current policies and external regulatory mandates before pursuing formal third-party validation.
Candidates frequently choose D (External examination) because they over-index on the word 'external,' failing to read the prompt's emphasis on 'gaining an understanding.' In reality, external examinations are formal, resource-intensive processes used for final certification or regulatory submission, not preliminary gap analysis.
Community Discussion (18 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Understanding the Compliance Assessment Hierarchy
When evaluating how organizational security policies align with external regulatory requirements (such as HIPAA, GDPR, PCI-DSS, or SOX), the first step is almost always a structured internal audit. An internal audit is conducted by the organization’s own compliance, risk, or IT teams to systematically review controls, document findings, and identify gaps against both internal standards and external mandates. As noted by multiple high-voted community members, the phrase 'would like to gain an understanding' signals a need for gap analysis and self-assessment, which does not require third-party involvement.Why External Examination Is a Distractor
Option D (External examination) refers to a formal, independent review conducted by qualified third parties (e.g., certified auditors or regulatory bodies). While highly valuable, these are typically reserved for final compliance certification, post-breach investigations, or contractual obligations—not for initial policy alignment studies. Relying on external exams prematurely wastes budget and time. The community correctly points out that you only escalate to an external examiner after internal controls have been mapped, tested, and remediated.Eliminating Technical and Formal Alternatives
- Penetration test (A) focuses on identifying technical vulnerabilities in systems and networks through simulated attacks. It does not evaluate policy documentation, procedural compliance, or regulatory alignment.
- Attestation (C) is a formal written declaration by a third party confirming that specific controls meet defined standards. It is the output or deliverable of an audit process, not the assessment tool itself.
Community Consensus & Practical Application
Multiple experienced candidates emphasize that internal audits serve as the foundational step in the GRC lifecycle. They allow the CISO to benchmark current practices, prioritize remediation efforts, and prepare evidence packages before engaging external validators. This sequential approach aligns with industry best practices and CompTIA’s emphasis on risk management efficiency and fiscal responsibility.Official Reference
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →